CVE-2026-54183Disclosure(apache / airflow)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does not disclose data the user could not otherwise obtain — the masking is a shoulder-surfing defense for the UI, not an access-control boundary. This is an incomplete-fix follow-up to CVE-2026-42358, whose fix made only the dictionary walk unbounded; lists, tuples, and sets beyond the depth limit remained unmasked in the UI. Deployments that applied the CVE-2026-42358 fix should also upgrade to address this residual case. Upgrade to apache-airflow 3.3.1 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-12: 2Mentions · 2026-08-17: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-17: 108-1208-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-122
Disclosure2
2026-08-171
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Apache Airflow, Information Disclosure via Incomplete Secrets Masking, #CVE-2026-54183 (MEDIUM) -DC-Aug2026-1525 https://dailycve.com/apache-airflow-information-disclosure-via-incomplete-secrets-masking-cve-2026-54183-medium-dc-aug2026-1525/

    Post summary

    A newly disclosed Medium‑severity Apache Airflow vulnerability (CVE‑2026‑54183) exposing incomplete secrets masking, with detailed technical classification but no PoC, exploit, patch, or evidence of active exploitation.

    0000035
    228 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54183 Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend in… https://www.cve.org/CVERecord?id=CVE-2026-54183 ----- Traducción: CVE-2026-54183 Apa… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑54183, describing a flaw in Apache Airflow’s secrets masker that hides sensitive values in the UI, without mention of attacks, exploits, or patches.

    0000028
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54183 Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend in… https://www.cve.org/CVERecord?id=CVE-2026-54183

    Post summary

    Apache Airflow’s secrets masker recursion‑depth limit flaw causes sensitive values to be hidden in the UI; no PoC, exploit, or patch information is included.

    000001.2K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more